Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 14 Mar 2001 11:24:08 +0100 (CET)
From:      "Hartmann, O." <ohartman@klima.physik.uni-mainz.de>
To:        <freebsd-stable@freebsd.org>
Cc:        <freebsd-questions@freebsd.org>
Subject:   SecureRPC/netid/keychanges
Message-ID:  <Pine.BSF.4.33.0103141106590.1861-100000@klima.physik.uni-mainz.de>

next in thread | raw e-mail | index | archive | help
Dear Sirs.

Obviously FreeBSD supports SecureRPC by some facilities to run at startup
time. In our NIS/YP domain the NIS master server runs rpc.ypupdated and
keyserv daemon, each user has an entry in /etc/publickey and there is the
/etc/.rootkey file generated.

On NIS master server I can change all keys without any problem, but from
slave servers and clients, all running keyserv properly, I'm not able to
change the key of a user (especially of mine); I receive the following
error message (on a client in our domain):

ohartman: /homes/ohartman: chkey
Generating new key for unix.ID_No@Domainname
Password:
Retype password:
Sending key change request to NIS_master
chkey: unable to update NIS database (7): Local resource allocation failure

In the master server's /etc/publickey file exists the user 'nobody' so it
should possible to create new keys and especially change existent keys (as
described in several additional literature and some netresources). It is
confusing me that chkey is about to be creating a new key, not changing an
existing key. And more confusing is the fact, that a local resource
allocation failure occurs. The basic question is, whether SecureRPC has the full
functionality in FreeBSD or not, especially SecureNFS in that way. I miss an
export option for NFS-exported, securized filesystems in /etc/exports and I miss
the /etc/netid file which is said to be present when SecureRPC is implemented
in FreeBSD (there is no manpage for netid although mentioned in mknetid(8).


--
MfG
O. Hartmann

ohartman@klima.physik.uni-mainz.de
----------------------------------------------------------------
IT-Administration des Institut fuer Physik der Atmosphaere (IPA)
----------------------------------------------------------------
Johannes Gutenberg Universitaet Mainz
Becherweg 21
55099 Mainz

Tel: +496131/3924662 (Maschinensaal)
Tel: +496131/3924144
FAX: +496131/3923532


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.33.0103141106590.1861-100000>